Skip to content
Search
paperAugust 2026Unreviewed

MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of Repositories

Jian Zhao, Shenao Wang, Qingyang Wu, Yanjie Zhao, Xiao Cheng, Hao-Yu Wang

Abstract

The widespread adoption of open source software (OSS) has introduced significant security risks, with malicious code poisoning attacks increasingly targeting public package registries and open-source platforms. Existing detection approaches, including heuristic-, learning-, and LLM-based methods, suffer from language-specific designs, limited generalization, and high analysis costs, making them unsuitable for large-scale multi-language analysis. To address these challenges, we propose MalTotal,

Categories

Framework mappings

OWASP Top 10 for LLM Applications
  • LLM04Data and Model Poisoning
MITRE ATLAS
  • AML.T0020Poison Training Data

Suggested from the entry's categories.

Cite

@misc{zhao2026maltotal,
  title = {{MalTotal: Cost-Effective and Language-Agnostic Malicious Code Poisoning Detection for Millions of Repositories}},
  author = {Jian Zhao and Shenao Wang and Qingyang Wu and Yanjie Zhao and Xiao Cheng and Hao-Yu Wang},
  year = {2026},
  month = aug,
  eprint = {2608.03232},
  archivePrefix = {arXiv},
  doi = {10.1145/3832228},
  url = {https://www.semanticscholar.org/paper/4ab91ee574adb3a457dd6e506a4cd327af5a1fd1}
}